Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
161 results
cacti-rce-cve-2022-46169-vulnerable-application preview

cacti-rce-cve-2022-46169-vulnerable-application

GitHubm3ssap0/cacti-rce-cve-2022-46169-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!

command-and-controlexploitationlabs-practice+3
1
3 years ago
CVE-2026-0001 preview

CVE-2026-0001

GitHubhorkimhab/cve-2026-0001

CVE-2026-0001. Do with your own risk

educationexploitationpayload-development+3
3 months ago
CVE-2023-30212-POC-DOCKER-FILE preview

CVE-2023-30212-POC-DOCKER-FILE

GitHubrishipatidar/cve-2023-30212-poc-docker-file

This repository provides a Docker container for simulating the CVE-2023-30212 vulnerability, allowing you to practice and understand its impact. It…

educationexploitationlabs-practice+3
13 years ago
commons-text-goat preview

commons-text-goat

GitHubtulhan/commons-text-goat

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

educationexploitationlabs-practice+3
13 years ago
CVE-2020-7115 preview

CVE-2020-7115

GitHubretr02332/cve-2020-7115

Create your malicious engine in seconds

exploitationpayload-generationpenetration-testing+3
15 years ago
Metasploit-Exploits-CVE-2023-6710 preview

Metasploit-Exploits-CVE-2023-6710

GitHubdedsec-47/metasploit-exploits-cve-2023-6710

Welcome to the Metasploit Exploits Repository, your go-to resource for a comprehensive collection of cutting-edge exploits designed for penetration…

educationexploit-frameworkspayload-development+4
12 years ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
11 year ago
CVE-2025-55182-Terminal preview

CVE-2025-55182-Terminal

GitHubmrsol0/cve-2025-55182-terminal

This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

exploitationpayload-generationpenetration-testing+3
9 months ago
gahoole77.github.io preview

gahoole77.github.io

GitHubgahoole77/gahoole77.github.io

🔍 Discover and scan vulnerable Next.js instances to protect your infrastructure from critical RCE vulnerabilities like CVE-2025-55182.

information-gatheringreconnaissancevulnerability-scanners+2
7 months ago
log4shell preview

log4shell

GitHubjxerome/log4shell

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

educationexploitationlabs-practice+3
4 years ago
cacti-rce-snmp-options-vulnerable-application preview

cacti-rce-snmp-options-vulnerable-application

GitHubm3ssap0/cacti-rce-snmp-options-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!

command-and-controleducationexploitation+3
1 year ago
lscript preview
Archived

lscript

GitHubarismelachroinos/lscript

The LAZY script will make your life easier, and of course faster.

exploit-frameworksinformation-gatheringpassword-attacks+7
4.3k5 years ago
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

anti-botapi-securityapi-security-testing+8
22.7k1 day ago
iDict preview

iDict

GitHubpr0x13/idict

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

authenticationexploitationpassword-attacks+3
9023 years ago
vulnerable-code-snippets preview

vulnerable-code-snippets

GitHubyeswehack/vulnerable-code-snippets

Twitter vulnerable snippets

code-analysiscurated-resourceseducation+3
1.2k7 months ago
CVE-2021-44228-PoC-log4j-bypass-words preview

CVE-2021-44228-PoC-log4j-bypass-words

GitHubpuliczek/cve-2021-44228-poc-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

educationexploitationids-ips-evasion+6
9494 years ago
php_filter_chain_generator preview

php_filter_chain_generator

GitHubsynacktiv/php_filter_chain_generator

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

exploitationpayload-developmentpayload-generation+2
1.1k3 years ago
Firefox-Security-Toolkit preview

Firefox-Security-Toolkit

GitHubmazen160/firefox-security-toolkit

A tool that transforms Firefox browsers into a penetration testing suite

educationinformation-gatheringosint+3
5171 year ago
Previous123…9Next